Selesta Visual Access Manager Incorrect Access Control Vulnerability Allowing Arbitrary SQL Query Execution

Vulnerability

A vulnerability exists in Selesta Visual Access Manager (VAM) versions prior to 4.42.2, where an authenticated user can access the administrative page '/common/vam_Sql.php'. This page permits the execution of arbitrary SQL queries, potentially leading to unauthorized data manipulation or disclosure.

Impact

Exploitation of this vulnerability could allow an authenticated user to execute arbitrary SQL queries, which may be used to manipulate or extract sensitive data from the application's database.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.